AgentVault MCP Server
# AgentVault SDK
The **official open-source client** for [AgentVault](https://www.vektraindustries.com) — the API-first password/secrets manager for AI agents. An agent gets a real vault, stores secrets encrypted at rest, and fetches exactly one credential at runtime via an `av://vault/secret/field` reference under a scoped, revocable token.
This package is MIT-licensed. The AgentVault **server** (vaults, AES-256-GCM encryption, scoped-token issuance, audit) is a Vektra Industries product.
## Install
```bash
pip install agentvault-sdk # or: uv pip install agentvault-sdk
```
## Use
```python
from agentvault_sdk import AgentVaultClient
av = AgentVaultClient("https://vault.example.com", token="av_...")
av.create_vault("prod")
av.put_secret("prod", "stripe", {"api_key": "sk_live_..."})
# fetch one secret at runtime — no hardcoded keys
key = av.resolve("av://prod/stripe/api_key")
```
## MCP server
Expose AgentVault tools to any MCP-capable agent over stdio:
```bash
export AGENTVAULT_URL=https://vault.example.com
export AGENTVAULT_TOKEN=av_...
agentvault-mcp
```
Tools: `av_create_vault`, `av_put_secret`, `av_get_secret`, `av_resolve`, `av_list_secrets`, `av_issue_token`, `av_rotate_secret`.
---
© 2026 Pablo Navarro / Vektra Industries. MIT.
TDQS
Scored across 7 tools
While av_get_secret and av_resolve both retrieve secret data, av_get_secret returns the full field map while av_resolve targets a specific field via reference. av_put_secret and av_rotate_secret are similarly distinct (create/update vs. replace). The purposes are mostly clear, though the boundary between get/resolve and put/rotate could momentarily confuse.
The av_ prefix is consistent, and most tools follow av_<verb>_<noun> (create_vault, put_secret, get_secret, list_secrets, issue_token, rotate_secret). The verb style is uniform, but 'av_resolve' lacks an explicit object, a minor deviation.
With 7 tools, the set is well-scoped for a vault management server, fitting the typical 3-15 range. Each tool addresses a distinct operation without redundancy or bloat.
The server covers the core lifecycle of vaults and secrets: create, read, update, list, rotate, and token issuance. However, there is no delete operation for vaults or secrets, which could be considered a gap for complete lifecycle management, though it may be intentional for security.